SB2017092808 - Security restrictions bypass in Siemens products
Published: October 4, 2017
Security Bulletin ID
SB2017092808
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2017-12736)
The vulnerability allows a adjacent attacker to bypass security restrictions on the target system.The weakness exists due to improper access controls in the RCDP implementation that is used by Siemens Ruggedcom ROS-based devices and Siemens Scalance X switch models. An adjacent attacker on the same collision or broadcast domain as the target system can bypass security restrictions, gain unauthorized access and perform administrative actions.
Remediation
Install update from vendor's website.